Abstract:
We consider the block iterative cipher Simon based on the Feistel network and its modification based on the Lai — Messi scheme. Received estimates of differentials of the considered ciphers are compared. The results show that after $12$ rounds, estimate of the maximum probability of a differential for the modified cipher Simon $32/64$ without adding an orthomorphism is $2^{-24}$, and with the addition of orthomorphism is between $2^{-24}$ and $2^{-63}$, while the estimate of maximum probability for the original version is $2^{-36}$.